EDCA-P09 · Governed by EDCA-STD-10
Remote Identity Proofing Certification
An assessment of a service that establishes a person's identity without meeting them. It examines how identity evidence is captured and checked for authenticity, how the applicant is bound to that evidence, when a human reviews the decision, and what record survives to show why the decision was taken.
This certification is an assessment of a service against the Agency's own standard. It is not qualification as a trust service provider under Regulation (EU) No 910/2014 as amended by Regulation (EU) 2024/1183, not a conformity assessment for the purposes of that Regulation, and not accreditation as a conformity assessment body. It confers no presumption of conformity with ETSI TS 119 461 or any other external standard, although the Agency's requirements draw on that body of work.
Scope of assessment
The scope is agreed in writing before the assessment begins and is printed on the certificate. A certificate says nothing outside its scope.
- Named identity proofing services and the assurance they claim
- Capture of identity evidence and its authenticity checks
- Binding of the applicant to the evidence, including liveness where used
- The automated decision and the human review path behind it
- Retention of evidence and of decision records
What is examined
Each area below is assessed against the requirements of EDCA-STD-10, Remote Identity Proofing, version 1.0.
- Authenticity checks applied to identity documents
- Presentation attack detection and liveness
- Binding of the person to the document
- Quality of automated extraction and comparison
- Human review: when it is triggered, by whom, against what criteria
- Retention, integrity and retrievability of evidence
- Measured error rates and how they are monitored over time
- Treatment of biometric and other special category data
Programme particulars
- Programme code
- EDCA-P09
- Governing standard
- EDCA-STD-10 — Remote Identity Proofing, version 1.0, issued 28 July 2026
- Levels available
-
Level II — EDCA Security Verified
Level III — EDCA Advanced Compliance
Level IV — EDCA Trusted Technology - Typical duration
- Twelve to eighteen weeks from application to decision.
- Surveillance
- As required by the level held. See level requirements.
Evidence normally requested
The list is indicative. The evidence request issued after the preliminary assessment is specific to the agreed scope.
- Service description stating the level of assurance claimed
- Inventory of document authenticity checks by document type
- Presentation attack detection testing results
- Extraction and comparison accuracy measurements
- Human review procedure and reviewer competence records
- Retention schedule and a demonstration of retrieval
- Data protection impact assessment
Apply for Remote Identity Proofing Certification
Submitting an application costs nothing and commits you to nothing. The Agency will confirm eligibility, propose a scope and issue a fee schedule before any assessment work begins.